Security

Security controls built into the measurement path.

Daively protects credentials, authenticates sensitive ingestion paths, scopes product access and keeps an audit trail of administrative actions.

Platform controls

Defense across identity, data and delivery

Credential encryption

Connection credentials and sensitive short-lived delivery snapshots are protected with AES-256-GCM encryption at rest.

Signed SDK requests

App-specific HMAC signatures, replay windows and secret rotation protect authenticated mobile measurement paths.

Role-based access

Owner, Editor, Ad Manager and Developer roles separate user management, financial data and technical integration access.

Two-factor authentication

TOTP enrollment includes replay protection, while password failures use rate limits, delay and account lockout.

Durable delivery

Conversion outboxes use bounded retries, leases, deduplication and scrub sensitive snapshots after their final state.

Audited operations

User, credential, export, privacy and configuration actions are recorded with actor, target and time.

Responsible disclosure

Report a security concern privately

Send a concise report to support@daively.com. Include the affected surface and reproduction steps, but do not include real customer credentials, personal data or advertising identifiers.

Contact security